XSS Vulnerability in Action View Tag Helpers for Ruby on Rails
CVE-2022-27777
Key Information:
- Vendor
Rubyonrails
- Vendor
- CVE Published:
- 26 May 2022
What is CVE-2022-27777?
A Cross-Site Scripting vulnerability exists in the Action View tag helpers of Ruby on Rails, specifically in versions greater than or equal to 5.2.0 and less than 5.2.0. This flaw allows attackers to inject malicious content into web applications by manipulating input into specified attributes. If an attacker can control specific input, they can potentially execute arbitrary script code in the context of the user's session, leading to the compromise of sensitive data and user impersonation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
https://github.com/rails/rails 7.0.2.4, 6.1.5.1, 6.0.4.8, 5.2.7.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
